logo

FIN7__2022__FIN7_TLPCLEAR.pdf

ID: a6ad7820-3cca-4f8a-bca7-677f675eba05

STIX ID: report--a6ad7820-3cca-4f8a-bca7-677f675eba05

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2022-12-22

Last Modified Date: 2022-12-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** This PRODAFT report provides a comprehensive investigation of the FIN7 cybercrime/APT group, exposing its hierarchical organization, tailored tooling (Tirion/Lizar, custom PowerShell droppers, loaders), large-scale automated attack platform for Microsoft Exchange (ProxyShell/ProxyLogon) and SQLi, social-engineering (BadUSB, spear-phishing) methods, ransomware affiliations (REvil, DarkSide, LockBit), victim prioritization processes, post-exploitation toolset (SSH backdoors, Cobalt Strike, rclone exfiltration), and a lengthy set of IOCs and hashes useful for detection and response.